1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
use crate::resource::{ResourceDefinition, ResourceOutputsDefinition, ResourceRef, ResourceType};
use crate::RemoteBindingsOutputs;
use alien_error::AlienError;
use bon::Builder;
use serde::{Deserialize, Serialize};
use std::any::Any;
use std::fmt::Debug;
/// Represents cross-account management access configuration for a stack deployed
/// on AWS, GCP, or Azure platforms. This resource sets up the necessary IAM/RBAC
/// configuration to allow another cloud account to manage the stack.
///
/// Maps to:
/// - AWS: Cross-account IAM role with management permissions
/// - GCP: Service account with management permissions and impersonation rights
/// - Azure: User-assigned managed identity with federated credential and custom RBAC
///
/// This resource is automatically created for AWS, GCP, and Azure platforms
/// when the stack needs to be managed by another account. The management account
/// and identity information comes from the platform configuration.
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize, Builder)]
#[cfg_attr(feature = "openapi", derive(utoipa::ToSchema))]
#[serde(rename_all = "camelCase", deny_unknown_fields)]
#[builder(start_fn = new)]
pub struct RemoteStackManagement {
/// Identifier for the remote stack management. Must contain only alphanumeric characters, hyphens, and underscores ([A-Za-z0-9-_]).
/// Maximum 64 characters.
#[builder(start_fn)]
pub id: String,
}
impl RemoteStackManagement {
/// The resource type identifier for RemoteStackManagement
pub const RESOURCE_TYPE: ResourceType = ResourceType::from_static("remote-stack-management");
/// Returns the remote stack management's unique identifier.
pub fn id(&self) -> &str {
&self.id
}
}
/// Resource outputs for RemoteStackManagement.
/// Different platforms will provide different outputs based on their implementation.
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
#[cfg_attr(feature = "openapi", derive(utoipa::ToSchema))]
#[serde(rename_all = "camelCase", deny_unknown_fields)]
pub struct RemoteStackManagementOutputs {
/// Platform-specific management resource identifier
/// For AWS: The ARN of the created cross-account role
/// For GCP: The email of the created service account
/// For Azure: The resource ID of the target user-assigned managed identity
pub management_resource_id: String,
/// Platform-specific access configuration
/// For AWS: The role ARN to assume
/// For GCP: The service account email to impersonate
/// For Azure: JSON containing the target managed identity client ID and tenant ID
pub access_configuration: String,
/// Read-only compatibility for deployments imported before Remote Bindings became a
/// first-class resource. New controllers never serialize this field.
#[serde(default, rename = "remoteBindingsAccess", skip_serializing)]
#[cfg_attr(feature = "openapi", schema(ignore))]
pub legacy_remote_bindings_access: Option<RemoteBindingsOutputs>,
}
// Implementation of ResourceDefinition trait for RemoteStackManagement
impl ResourceDefinition for RemoteStackManagement {
fn get_resource_type(&self) -> ResourceType {
Self::RESOURCE_TYPE
}
fn id(&self) -> &str {
&self.id
}
fn get_dependencies(&self) -> Vec<ResourceRef> {
// RemoteStackManagement typically doesn't depend on other resources,
// but may depend on infrastructure requirements like resource groups
Vec::new()
}
fn validate_update(&self, new_config: &dyn ResourceDefinition) -> crate::error::Result<()> {
// Try to downcast to RemoteStackManagement for type-specific validation
if let Some(new_remote_mgmt) = new_config.as_any().downcast_ref::<RemoteStackManagement>() {
// Validate that the ID matches
if self.id != new_remote_mgmt.id {
return Err(AlienError::new(
crate::error::ErrorData::InvalidResourceUpdate {
resource_id: self.id.clone(),
reason: "the 'id' field is immutable".to_string(),
},
));
}
// RemoteStackManagement configuration can be updated
Ok(())
} else {
Err(AlienError::new(
crate::error::ErrorData::UnexpectedResourceType {
resource_id: self.id.clone(),
expected: Self::RESOURCE_TYPE,
actual: new_config.get_resource_type(),
},
))
}
}
fn as_any(&self) -> &dyn Any {
self
}
fn as_any_mut(&mut self) -> &mut dyn Any {
self
}
fn box_clone(&self) -> Box<dyn ResourceDefinition> {
Box::new(self.clone())
}
fn resource_eq(&self, other: &dyn ResourceDefinition) -> bool {
other
.as_any()
.downcast_ref::<RemoteStackManagement>()
.map(|other_remote_mgmt| self == other_remote_mgmt)
.unwrap_or(false)
}
fn to_json_value(&self) -> serde_json::Result<serde_json::Value> {
serde_json::to_value(self)
}
}
impl ResourceOutputsDefinition for RemoteStackManagementOutputs {
fn get_resource_type(&self) -> ResourceType {
RemoteStackManagement::RESOURCE_TYPE.clone()
}
fn as_any(&self) -> &dyn Any {
self
}
fn box_clone(&self) -> Box<dyn ResourceOutputsDefinition> {
Box::new(self.clone())
}
fn outputs_eq(&self, other: &dyn ResourceOutputsDefinition) -> bool {
other
.as_any()
.downcast_ref::<RemoteStackManagementOutputs>()
== Some(self)
}
fn to_json_value(&self) -> serde_json::Result<serde_json::Value> {
serde_json::to_value(self)
}
}
#[cfg(test)]
mod tests {
use super::RemoteStackManagementOutputs;
#[test]
fn legacy_remote_bindings_output_remains_readable_but_is_not_reemitted() {
let outputs: RemoteStackManagementOutputs = serde_json::from_value(serde_json::json!({
"managementResourceId": "management",
"accessConfiguration": "management-access",
"remoteBindingsAccess": {
"resourceId": "legacy-bindings",
"accessConfiguration": "legacy-access"
}
}))
.expect("legacy persisted output must remain readable");
assert_eq!(
outputs
.legacy_remote_bindings_access
.as_ref()
.map(|access| access.resource_id.as_str()),
Some("legacy-bindings")
);
assert!(
serde_json::to_value(outputs)
.expect("serialize")
.get("remoteBindingsAccess")
.is_none(),
"new state must not keep writing the legacy ownership slot"
);
}
}